{"schema_version":1,"experiment_id":"eoa_inverse_innovation_exp04_retrieval_first_paired20_20260802","cell_id":"deadweight_loss_reduction__systems_cybernetics","hypothesis_id":"H2","search_queries":["industrial control system management of change risk based low risk controller parameter change parallel approval sandbox deployment","process control controller tuning change management risk assessment approval workflow low risk","IEC 61511 management of change modification impact analysis safety instrumented system controller official","industrial automation digital twin sandbox controller changes validation deployment rollback","\"risk-tiered\" \"PLC\" change management staging simulation approval","\"minor change\" management of change process control system risk assessment approval","patent risk based approval controller change sandbox deployment industrial control","standard change pre-authorized industrial control system PLC change management"],"sources":[{"source_id":"S1","title":"1910.119 App C — Compliance Guidelines and Recommendations for Process Safety Management","publisher":"U.S. Occupational Safety and Health Administration","url":"https://www.osha.gov/laws-regs/regulations/standardnumber/1910/1910.119AppC","source_class":"GOVERNMENT_OR_REGULATOR","claims_supported":["Process-safety management of change expressly covers equipment, instrumentation, computer-program, alarm, interlock, and operating-parameter changes.","OSHA already recommends differentiated scrutiny: a minor, well-understood change may use an authorized-person checklist, while significant changes may require hazard evaluation and approvals from operations, maintenance, and safety departments.","Temporary changes require time limits, monitoring, documentation, and restoration to the designed condition."]},{"source_id":"S2","title":"6.5 Configuration Management","publisher":"NASA","url":"https://www.nasa.gov/reference/6-5-configuration-management/","source_class":"OFFICIAL_GUIDANCE","claims_supported":["NASA configuration management distinguishes major from minor engineering changes and assigns an appropriate change-control authority.","NASA identifies criteria-based workflow routing, verification, traceability, status tracking, and time-in-phase metrics as configuration-management capabilities."]},{"source_id":"S3","title":"IEC 62443 Change Management Software for OT","publisher":"VEM","url":"https://getvem.com/platform/ot-change-management/iec-62443","source_class":"COMMERCIAL_FIRST_PARTY","claims_supported":["A commercial OT product already manages approval, deployment, verification, and audit evidence for PLC, SCADA, HMI, setpoint, safety-threshold, and machine-parameter changes.","Its documented workflow permits CAB or single-approver review of the change diff, risk, and deployment plan, then controlled deployment with before-and-after controller signatures."]},{"source_id":"S4","title":"Configure Risk for Simplified Change Management","publisher":"ServiceNow","url":"https://www.servicenow.com/docs/r/it-service-management/configure-risk-change-mgmt.html","source_class":"OFFICIAL_PRODUCT_DOCUMENTATION","claims_supported":["A deployed change-management product calculates Low, Moderate, or High risk from scored questions and automatically routes each request to the matching approval workflow.","Risk thresholds and approval routing are configurable rather than uniform across changes."]},{"source_id":"S5","title":"Canarying Releases","publisher":"Google Site Reliability Engineering","url":"https://sre.google/workbook/canarying-releases/","source_class":"OFFICIAL_GUIDANCE","claims_supported":["Release automation explicitly seeks steps that can be parallelized, reduces repetitive manual work, and measures time to production and failure rates.","Canary deployment limits exposure, compares the candidate with a control, monitors predefined metrics, and pauses or rolls back when degradation is detected."]},{"source_id":"S6","title":"Sandbox-Enabled Digital Twin for Cyber-Physical Systems","publisher":"Udeshi et al. (arXiv)","url":"https://arxiv.org/abs/2606.17001","source_class":"PRIMARY_RESEARCH","claims_supported":["A closed-loop sandbox can run an unmodified controller binary against a plant simulator while collecting controller and plant observations.","The authors demonstrate the framework with OpenPLC controlling an IEEE 14-bus power-system model and support repeatable fault-injection and scenario testing, although they do not evaluate an approval workflow or production safety outcomes."]},{"source_id":"S7","title":"US10664380B2 — Risk-based software validation and change control","publisher":"Google Patents / U.S. patent record","url":"https://patents.google.com/patent/US10664380B2/en","source_class":"STANDARD","claims_supported":["The patent, with 2018 priority, calculates feature-level risk and uses change scope, integration, usage, and testing evidence to select only the portions requiring client-specific validation.","It expressly frames selective validation as avoiding validation of every module on every upgrade and reducing validation and reporting time."]},{"source_id":"S8","title":"IEC 61511 Functional Safety in the Process Industry: The Long-Awaited Edition 2 and What It Means for the Process Industry","publisher":"Institution of Chemical Engineers","url":"https://www.icheme.org/media/11752/hazards-26-paper-15-iec-61511-functional-safety-in-the-process-industry-the-long-awaited-iec-61511-edition-2-and-what-it-means-for-the-process-industry.pdf","source_class":"AUTHORITATIVE_SECONDARY","claims_supported":["The IEC 61511 analysis reports that modifications require impact analysis and may require review or revalidation of lifecycle evidence.","For safety-instrumented-system application-program changes, full validation and proof testing remain expected, establishing a boundary that a lighter pathway cannot silently remove."]}],"proximity":"SUBSTANTIAL_COLLISION","closest_analogues":[{"name":"OSHA risk-differentiated management of change for process instrumentation","similarity":"Directly covers controller-adjacent instrumentation, computer programs, alarms, interlocks, and parameter changes, and already replaces multidisciplinary approval with an authorized-person checklist when impact is minor and well understood.","remaining_difference":"It does not prescribe parallel review, a controller sandbox, or comparative deployment-time and safety-outcome measurement.","source_ids":["S1"]},{"name":"VEM controlled OT change workflow","similarity":"Commercial first-party documentation covers PLC logic, setpoints, safety thresholds, risk review, single-approver or CAB treatment, controlled deployment, verification evidence, and controller baselines.","remaining_difference":"The opened documentation does not establish hazard-and-reversibility eligibility, parallel review, sandbox execution, or evaluated noninferiority outcomes.","source_ids":["S3"]},{"name":"Risk-routed approval plus canary deployment in IT operations","similarity":"ServiceNow supplies automatic risk-tier routing, while Google supplies parallelizable release pipelines, bounded candidate exposure, predefined monitoring, and rollback.","remaining_difference":"These sources concern IT services rather than hazardous physical-process controller changes and therefore do not establish safety equivalence in an industrial plant.","source_ids":["S4","S5"]},{"name":"Risk-based selective software validation","similarity":"The patent scores change risk and scopes validation to changed, integrated, and actually used portions instead of validating every module after every upgrade.","remaining_difference":"It does not address plant-controller authorization, functional-safety obligations, parallel approval, or monitored physical-process deployment.","source_ids":["S7"]},{"name":"Closed-loop controller sandbox and digital twin","similarity":"Primary research demonstrates isolated execution of an unmodified PLC runtime against a simulated physical plant with synchronized observation and repeatable scenarios.","remaining_difference":"It is a testing framework, not a risk-tiered management-of-change process, and supplies no production deployment or six-month incident evidence.","source_ids":["S6"]}],"overlapping_components":["Risk classification of individual change requests","Lighter authorization for minor or well-understood changes","Full multidisciplinary scrutiny for significant or safety-relevant changes","Controller and instrumentation change control","Criteria-based approval routing","Impact analysis and selective validation","Parallelizable automated release workflow","Sandbox or simulated-plant validation","Bounded monitored rollout and rollback","Before-and-after configuration evidence","Audit trail and verification","Predefined safety or service metrics"],"remaining_contrastive_claim":"The bounded search did not locate an evaluated industrial-control implementation that combines hazard-and-reversibility eligibility, parallel approval, closed-loop sandbox deployment, preserved full functional-safety scrutiny for high-risk cases, and a demonstrated 30% deployment-time reduction without worse safety-violation or rollback rates.","claim_falsifier":"A pre-existing operator case study, product manual, patent, standard workflow, or controlled evaluation documenting that complete end-to-end combination for live industrial controller changes—especially with deployment-time and safety or rollback comparisons—would falsify the remaining claim.","problem_support":"WEAK","recommendation":"REJECT","world_novelty_boundary":"Risk-tiered change scrutiny, selective validation, criteria-based approval routing, controller simulation, monitored rollout, and rollback are all prior art; only their exact hazardous-controller integration and outcome evaluation remain unlocated, and this bounded eight-query search cannot establish worldwide novelty."}